CVE-2026-42524
published 2026-04-29CVE-2026-42524: Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS)…
PriorityP336high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
0.28%
20.0th percentile
Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | credentials_binding | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | github | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source_plugin | — | — |
| jenkins | github_plugin | — | — |
| jenkins | html_publisher | <= 427 | — |
| jenkins | html_publisher | — | — |
| jenkins | html_publisher_plugin | — | — |
| jenkins | matrix_authorization_strategy | — | — |
| jenkins | matrix_authorization_strategy_plugin | — | — |
| jenkins | script_security | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins_project | jenkins_html_publisher_plugin | <= 427 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper file
ghsa·2026-04-29
CVE-2026-42524 [HIGH] CWE-79 Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper file
Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper file
Jenkins HTML Publisher Plugin versoins 427 and earlier do not escape the job name and URL in the legacy wrapper file.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
HTML Publisher Plugin 427.1 escapes job name and URL when generating the legacy wrapper file.
VulDB
Jenkins HTML Publisher Plugin up to 427 cross site scripting (EUVD-2026-26226 / Nessus ID 310885)
vuldb·2026-04-29·CVSS 8.0
CVE-2026-42524 [HIGH] Jenkins HTML Publisher Plugin up to 427 cross site scripting (EUVD-2026-26226 / Nessus ID 310885)
A vulnerability, which was classified as problematic, was found in Jenkins HTML Publisher Plugin up to 427. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-42524. The attack can be launched remotely. No exploit exists.
Jenkins
Jenkins Security Advisory 2026-04-29
vendor_jenkins·2026-04-29·CVSS 4.3
CVE-2026-42519 [MEDIUM] Jenkins Security Advisory 2026-04-29
Title: Jenkins Security Advisory 2026-04-29
Jenkins Security Advisory 2026-04-29
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Credentials Binding
Plugin
GitHub
Plugin
GitHub Branch Source
Plugin
HTML Publisher
Plugin
Matrix Authorization Strategy
Plugin
Microsoft Entra ID (previously Azure AD)
No detection rules found.
No public exploits indexed.
2026-04-29
Published